fake-whatsapp-star-blizzard

How Russian hackers went after NGOs’ WhatsApp accounts

Share:

Star Blizzard, a threat actor tied to the Russian Federal Security Service (FSB), was spotted attempting to compromise targets’ WhatsApp accounts through a clever phishing campaign.

The campaign

The campaign started with a spear-phishing email that was made to look like it was sent by a US government official.

“We have established a private WhatsApp group to facilitate discussions regarding the latest non-govermental initiatives aimed at supporting Ukraine. This platform will also serve as a means to coordinate the distribution of government-allocated funds for this purpose,” the email says. “You can join us using this QR code below.”

The QR code doesn’t work, though, pushing the victim to reply to say as much. Then, the attackers send a second email, with a shortened link instead of a QR code.

The link leads to a spoofed WhatsApp webpage asking them to go through several steps to join the group.

The spoofed WhatsApp page, with the QR code obscured (Source: Microsoft Threat Intelligence)

“However, this QR code is actually used by WhatsApp to connect an account to a linked device and/or the WhatsApp Web portal,” Microsoft’s threat analysts explained.

“This means that if the target follows the instructions on this page, the threat actor can gain access to the messages in their WhatsApp account and have the capability to exfiltrate this data using existing browser plugins, which are designed for exporting WhatsApp messages from an account accessed via WhatsApp Web.”

About Star Blizzard

The campaign seems to have been aimed at non-governmental organization (NGO) employees and, according to Microsoft, it started in mid-November and ended by the end of the month.

Nevertheless, it shows how Star Blizzard changes its tactics, techniques, and procedures (TTPs) and persists in achieving its goals.

“Star Blizzard’s targets are most commonly related to government or diplomacy (both incumbent and former position holders), defense policy or international relations researchers whose work touches on Russia, and sources of assistance to Ukraine related to the war with Russia,” the threat analysts noted.

They’ve also been known to target Russian citizens residing in the US, UK citizens, and computer networks belonging to NATO.

In late 2024, the Microsoft and the US Justice Department seized 100+ domains used the group, ans set the stage for further disruption any new infrastructure through an existing court proceeding.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
1:29 pm, Jul 2, 2025
weather icon 18°C
L: 17° | H: 19°
broken clouds
Humidity: 84 %
Pressure: 1017 mb
Wind: 8 mph WNW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:48 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 19°°C 0.2 mm 20% 11 mph 75 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
14° | 26°°C 0 mm 0% 11 mph 57 % 1028 mb 0 mm/h
Fri Jul 04 10:00 pm
weather icon
15° | 26°°C 0 mm 0% 12 mph 61 % 1028 mb 0 mm/h
Sat Jul 05 10:00 pm
weather icon
16° | 18°°C 1 mm 100% 13 mph 97 % 1021 mb 0 mm/h
Sun Jul 06 10:00 pm
weather icon
14° | 20°°C 1 mm 100% 12 mph 93 % 1007 mb 0 mm/h
Today 4:00 pm
weather icon
19° | 21°°C 0.2 mm 20% 8 mph 75 % 1018 mb 0 mm/h
Today 7:00 pm
weather icon
21° | 23°°C 0 mm 0% 11 mph 45 % 1018 mb 0 mm/h
Today 10:00 pm
weather icon
18° | 18°°C 0 mm 0% 11 mph 32 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
14° | 14°°C 0 mm 0% 7 mph 43 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
14° | 14°°C 0 mm 0% 5 mph 56 % 1026 mb 0 mm/h
Tomorrow 7:00 am
weather icon
15° | 15°°C 0 mm 0% 5 mph 57 % 1028 mb 0 mm/h
Tomorrow 10:00 am
weather icon
20° | 20°°C 0 mm 0% 5 mph 39 % 1028 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
23° | 23°°C 0 mm 0% 5 mph 29 % 1028 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,360.92
0.75%
Ethereum(ETH)
€2,079.54
-0.07%
Tether(USDT)
€0.85
-0.01%
XRP(XRP)
€1.86
-1.03%
Solana(SOL)
€125.84
-0.51%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.137049
0.41%
Shiba Inu(SHIB)
€0.000009
1.00%
Pepe(PEPE)
€0.000008
0.15%
Scroll to Top